PT-2026-28434 · Coreos+1 · Flannel+1

CVE-2026-32241

·

Publicado

2026-03-18

·

Atualizado

2026-07-30

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Flannel versions prior to 0.28.2
Description Flannel, a network fabric for containers designed for Kubernetes, contains a command injection issue in its experimental Extension backend. An attacker who can set Kubernetes Node annotations can achieve root-level arbitrary command execution on every flannel node in the cluster. The Extension backend’s SubnetAddCommand and SubnetRemoveCommand receive attacker-controlled data via stdin from the flannel.alpha.coreos.com/backend-data Node annotation, which is then piped directly to a shell command without validation. Kubernetes clusters using Flannel with the Extension backend are affected; other backends like vxlan and wireguard are not impacted.
Recommendations Versions prior to 0.28.2 should be updated to version 0.28.2 or later. As a workaround, use Flannel with a different backend such as vxlan or wireguard.

Exploit

Correção

DoS

RCE

Command Injection

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-80972
BDU:2026-07361
CVE-2026-32241
GHSA-VCHX-5PR6-FFX2
GO-2026-4894
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1205-1

Produtos afetados

Flannel
Red Os